A recent security breach exposed 38 terabytes of critical information from a Microsoft employee who unintentionally shared open-source AI training data on GitHub. Cybersecurity specialists at Wiz Research discovered the leak and Microsoft was informed right away. No customer data or other internal services were compromised, according to Microsoft’s Security Response Center team. The leak was caused by an excessively permissive Shared Access Signature (SAS) token set up incorrectly with full-control rights. Over 30,000 internal Microsoft Teams messages from 359 Microsoft workers were exposed, along with secret keys and passwords for Microsoft services. Microsoft acted quickly to stop external access to the storage account by removing the SAS token.
